Record summary

CVE-2002-0495 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBCSSearch 2.3 - Remote Command ExecutionExploitDB exploitby Steve GustinNot analyzed1 file
ExploitDB

PoC details

References

5